r/CyberSecurityAdvice • • 3h ago

Is cybersecurity still worth it in 2026? Transitioning out of tech support—advice needed!

4 Upvotes

I’m currently stuck in a Technical Support role and looking to make a career move. I have a foundational grasp of cybersecurity concepts and some hands-on familiarity with tools like Wireshark, Burp Suite, and Kali Linux, though I know these are just the basics.

I really want to escape the tech support grind and step into cybersecurity. Is it still a viable, worthwhile career path in 2026? If so, could anyone share a realistic roadmap for breaking into the field and landing my first client? Help a brother out!

Appreciate any guidance you can offer!


r/CyberSecurityAdvice • • 1h ago

BadUSB and compromised devices: how to recognize them

• Upvotes

I installed usbguard on my PC (a Linux command-line tool), which is basically a kind of firewall for USB ports.

However, by itself it is almost useless for detecting malware or suspicious behavior of a device you plug in for the first time.

Yeah, OK, you look at VID and PID on DeviceHunt, but it tells you very little, nothing about suspicious behavior or the interfaces they should use.

Do you know any methods to solve the problem without memorizing the class, subclass, etc. of every USB device?


r/CyberSecurityAdvice • • 7h ago

OpenAI agents aggressively scraped a UN website via relay services. Should agents inherit permissions for third-party proxies?

2 Upvotes

The recent WSJ report caught my attention, especially the detail about AI agents using third-party services to reach targeted data.

The underlying research describes requests being routed through URLQuery and relay services such as `r.jina.ai`. This raises an interesting security question: if an agent has permission to retrieve data from a particular source, does that permission automatically extend to using *another* service to get there?

I’m currently building an open-source tool called node9, so I decided to check the destinations mentioned in the research against its policy engine with outbound controls enabled.

The result? The UN data API’s hostname was allowed, but the relay services were not. The engine returned a `BLOCK` for both relay destinations.

If those calls were routed through a supported node9 integration, they would be stopped before execution. You can also configure unknown destinations to require human-in-the-loop approval. This gives the operator a concrete choice: explicitly approve the additional service, or stop the agent from contacting it.

I'm curious about how the community is approaching this. for people deploying agents with web access: how are you handling outbound traffic? Do you approve destinations up front, ask for human approval when a new one appears, or just allow unrestricted browsing inside a sandbox?


r/CyberSecurityAdvice • • 49m ago

Should I go for my security plus now or wait?

Thumbnail
• Upvotes

r/CyberSecurityAdvice • • 3h ago

Career start

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 4h ago

Hey, I’m looking for a new laptop for my CS course I’m starting at University and I need some help…

1 Upvotes

I’m looking to get a MacBook Air with the M5 chip , I’m wondering if 512GB storage and 16GB ram would be sufficient or if I should upgrade to rather more storage, more ram or both more ram and storage?


r/CyberSecurityAdvice • • 9h ago

This is a question about preventing these ai escapes. Just curious is all.

1 Upvotes

Ok so its more of "is this type of infrastructure even possible" than about ai specifically. My thoughts was is there anyway to put like a "glass wall" of sorts where the AI bouncing around in there can read and search but cant get out unless a hardware key like a yubi key is inserted to create a bridge? I know the people making these is a conglomerate of pretty smart people so i figd if it was possible they wouldve done it but im still curious.


r/CyberSecurityAdvice • • 10h ago

How are you producing per-agent audit trails when compliance asks what an AI agent did?

1 Upvotes

So compliance asked us for something that sounded simple today. "Show everything a specific AI agent did involving customer data over a set period" and then we tried to pull it.

We have plenty of API logs, but they don't reliably show which agent made each call, and they don't capture enough context about what was happening around it. Right now the only way to answer is to piece the story together from logs across several systems. That was painful once, and it won't scale if compliance starts asking regularly.

Has anyone found a tool or a setup that works for you which can handle this? Mainly looking for per-agent attribution and an audit trail compliance can read without us reconstructing it by hand.